← Back to Baseline

MB-R248

HUMAN VERIFICATION REQUIRED ASVS 10.3.3 Stable user identity (when oauth_oidc is used)

MB-C16 ASVS Level 2 Contextual Human Assurance High

If an access control decision requires identifying a unique user from an access token (JWT or related token introspection response), the resource server identifies the user from claims that cannot be reassigned to other users. Typically, it means using a combination of 'iss'and 'sub'claims.